Impact
The Hoo Companion WordPress plugin version 1.0.2 suffers from an unauthenticated stored cross-site scripting flaw in its theme-settings import function. The code accepts data without authentication or sanitization and stores it as the active theme's settings. When a site visitor loads the page, the malicious script executes in their browser, enabling credential theft, session hijacking, defacement, or other malicious actions. The weakness aligns with CWE-79: Improper Neutralization of Input during Web Page Generation.
Affected Systems
Any WordPress installation that has the Hoo Companion plugin 1.0.2 in use is affected. The flaw is independent of the active theme or WordPress core version; any user who browses the site—including administrators—will execute the injected script.
Risk and Exploitability
The CVSS score of 8.8 categorizes the flaw as high severity. Since no authentication is required and the input is not sanitized, exploitation is straightforward: an attacker simply crafts a request to the import endpoint and publishes a malicious payload. The script resides in the theme settings and will persist until the settings are overwritten or the plugin is at risk. The vulnerability is not currently listed in the CISA KEV catalog and the EPSS score is <1%, but the high severity and lack of controls make it a priority to patch.
OpenCVE Enrichment